CVE-2006-5806
published 2006-11-08CVE-2006-5806: SSL VPN Client in Cisco Secure Desktop before 3.1.1.45, when configured to spawn a web browser after a successful connection, stores sensitive browser session…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.34%
26.3th percentile
SSL VPN Client in Cisco Secure Desktop before 3.1.1.45, when configured to spawn a web browser after a successful connection, stores sensitive browser session information in a directory outside of the CSD vault and does not restrict the user from saving files outside of the vault, which is not cleared after the VPN connection terminates and allows local users to read unencrypted data.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure_desktop | <= 3.1.1.33 | — |
| cisco | secure_desktop | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco Secure Desktop up to 3.1.1.45 information disclosure (XFDB-30129 / BID-20964)
vuldb·2026-04-27·CVSS 2.1
CVE-2006-5806 [LOW] Cisco Secure Desktop up to 3.1.1.45 information disclosure (XFDB-30129 / BID-20964)
A vulnerability labeled as problematic has been found in Cisco Secure Desktop up to 3.1.1.45. This affects an unknown function. The manipulation results in information disclosure.
This vulnerability is known as CVE-2006-5806. Access to the local network is required for this attack. No exploit is available.
The affected component should be upgraded.
VulDB
Cisco Secure Desktop up to 3.1.1.45 SSL VPN Web Browser (XFDB-30129 / BID-20964)
vuldb·2026-04-27·CVSS 2.1
CVE-2006-5806 [LOW] Cisco Secure Desktop up to 3.1.1.45 SSL VPN Web Browser (XFDB-30129 / BID-20964)
A vulnerability identified as problematic has been detected in Cisco Secure Desktop up to 3.1.1.45. The impacted element is an unknown function of the component SSL VPN Web Browser. The manipulation leads to an unknown weakness.
This vulnerability is traded as CVE-2006-5806. Access to the local network is required for this attack to succeed. There is no exploit available.
You should upgrade the affected component.
VulDB
Cisco Secure Desktop up to 3.1.1.45 NTFS Install Directory information disclosure (XFDB-30129 / SBV-13072)
vuldb·2026-04-27·CVSS 2.1
CVE-2006-5806 [LOW] Cisco Secure Desktop up to 3.1.1.45 NTFS Install Directory information disclosure (XFDB-30129 / SBV-13072)
A vulnerability marked as problematic has been reported in Cisco Secure Desktop up to 3.1.1.45. This impacts an unknown function of the component NTFS Install Directory Handler. This manipulation causes information disclosure.
This vulnerability is handled as CVE-2006-5806. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-v6m5-m945-2767: SSL VPN Client in Cisco Secure Desktop before 3
ghsa_unreviewed·2022-05-01
CVE-2006-5806 [LOW] GHSA-v6m5-m945-2767: SSL VPN Client in Cisco Secure Desktop before 3
SSL VPN Client in Cisco Secure Desktop before 3.1.1.45, when configured to spawn a web browser after a successful connection, stores sensitive browser session information in a directory outside of the CSD vault and does not restrict the user from saving files outside of the vault, which is not cleared after the VPN connection terminates and allows local users to read unencrypted data.
Cisco
Multiple Vulnerabilities in Cisco Secure Desktop
vendor_cisco·2006-11-08·CVSS 7.0
CVE-2006-5806 [HIGH] CWE-200 Multiple Vulnerabilities in Cisco Secure Desktop
Multiple Vulnerabilities in Cisco Secure Desktop
Cisco Secure Desktop (CSD) software is affected by three
vulnerabilities that may:
Cause information produced and accessed during an Internet browsing
session to be left behind on a computer after an SSL VPN session terminates.
Allow users to evade the system policy that prevents them from
leaving the Secure Desktop while a VPN connection is active.
Allow local users to elevate their privileges.
Cisco has made free software available to address these
vulnerabilities for affected customers. There are workarounds available to
mitigate the effects of some of these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20061108-csd.
Cisco
Multiple Vulnerabilities in Cisco Secure Desktop
vendor_cisco
CVE-2006-5806 Multiple Vulnerabilities in Cisco Secure Desktop
CVE-2006-5806: Multiple Vulnerabilities in Cisco Secure Desktop
Cisco Secure Desktop (CSD) software is affected by three vulnerabilities that may: Cause information produced and accessed during an Internet browsing session to be left behind on a computer after an SSL VPN session terminates. Allow users to evade the system policy that prevents them from leaving the Secure Desktop while a VPN connection is active. Allow local users to elevate their privileges. Cisco has made free software available to address these vulnerabilities for affected customers. There are
CWE: CWE-200, CWE-264, CWE-200, CWE-264
Bug IDs: CSCsg05935, CSCsg11636, CSCsg29650, CSCsg05935
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/22747http://securitytracker.com/id?1017195http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtmlhttp://www.osvdb.org/30306http://www.securityfocus.com/bid/20964http://www.vupen.com/english/advisories/2006/4409https://exchange.xforce.ibmcloud.com/vulnerabilities/30129http://secunia.com/advisories/22747http://securitytracker.com/id?1017195http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtmlhttp://www.osvdb.org/30306http://www.securityfocus.com/bid/20964http://www.vupen.com/english/advisories/2006/4409https://exchange.xforce.ibmcloud.com/vulnerabilities/30129
2006-11-08
Published